Security

Last updated 9 September 2026

Signing in

Access is only through Google or Apple. No password is created, stored, or handled here, so there is none to be stolen. Whatever protection you have on that account — including two-step verification — protects this one too.

Separation between accounts

Every stored row carries the account that owns it, and the database enforces ownership on each request rather than trusting the app. A request for another member's ritual, CV, certificates, donations, attendance records or glossary terms returns nothing, even if it were deliberately crafted.

Uploaded certificates

Certificate files are held in a private store, never a public web address. Each file sits in a folder belonging to your account, and viewing one creates a link that only works for you and expires after ten minutes.

In transit and at rest

All traffic is encrypted over HTTPS, and the database is encrypted on disk with regular backups by the hosting provider.

Sensible precautions

Reporting a problem

If you notice anything that looks like a weakness, please report it to the person running this site before mentioning it elsewhere.

Back to Blue Acacia